Skip to content
CAI
Software that uses CAICheck a score

opifex/symfony

65.7

Adequate · 21 September 2026

6.8k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Symfony-based backend service implementing a CQRS architecture to manage user accounts and handle authentication via JWT tokens. It exposes RESTful APIs for account lifecycle operations, including creation, retrieval, and administrative controls, while supporting PayPal webhook integrations for payment events. The system is built with a strong emphasis on domain-driven design, featuring robust infrastructure for message handling, observability, and security.

How it got here

2023 — Initial Symfony scaffolding and core infrastructure

17 changes.

This period established the foundational architecture of the application by scaffolding a Symfony 8.1 project with Docker, CI/CD tooling, and static analysis configurations. It implemented the core presentation layer, including CQRS-based controllers for authentication and admin account management, alongside essential infrastructure like health checks and email templates.

2024–2025 — Core domain and infrastructure foundation

27 changes.

This period focused on establishing the foundational architecture for the account management system, including the domain model, Doctrine persistence layer, and Symfony infrastructure components. It introduced core services for authentication, messaging, and logging, while implementing strict validation and error handling mechanisms across the HTTP and application layers.

2026 — Core account management and security infrastructure

18 changes.

This period focused on establishing the foundational architecture for account management and security, introducing domain contracts, JWT-based authentication, and password hashing. It also implemented essential application-layer command and query handlers for account lifecycle operations alongside infrastructure components for observability, caching, and event handling.

Features

Added Doctrine Migrations template for generating migration classes

A new Twig template (migration.php.twig) has been added to the DoctrineMigrationsBundle presentation layer. This template provides the standard PHP structure for Doctrine DBAL migrations, including the AbstractMigration base class, up/down method signatures, and namespace/class placeholders, enabling the generation of properly formatted migration files.

src/Presentation/Resource/Template/bundles/DoctrineMigrationsBundle · high confidence

Added Doctrine mapping for the Account entity

Introduced the Doctrine ORM mapping for the Account entity, defining the 'account' table structure with fields for email, password, locale, roles, and status. The mapping includes a unique constraint on the email address (excluding soft-deleted records), lifecycle callbacks to automatically update the 'updated\_at' timestamp, and support for optimistic locking via a version column.

src/Infrastructure/Doctrine/Mapping · high confidence

Added GitHub Actions and TeamCity report formats for PHP\_CodeSniffer

The system now supports two new output formats for PHP\_CodeSniffer analysis results. The new PhpcsGithubReport class formats linting errors and warnings as GitHub Actions workflow commands, enabling direct integration with GitHub's code scanning and pull request annotations. The new PhpcsTeamcityReport class formats results using TeamCity service messages, allowing CI/CD pipelines running on TeamCity to display inspection types and individual issues with proper severity and fixability metadata.

config/markup/Reports · high confidence

Added JSON-based login authenticator with rate limiting

A new JsonLoginAuthenticator class has been introduced to handle JSON payload authentication requests. This component enforces rate limiting on login attempts by tracking both the email/IP combination and the IP address alone, throwing a TooManyRequestsHttpException if limits are exceeded. It supports interactive authentication flows and creates standard username/password tokens upon successful validation.

src/Infrastructure/Security/Authenticator · high confidence

Added PHP code quality configuration for PHPCS and PHPStan

Introduced configuration files for PHP\_CodeSniffer (phpcs.xml) and PHPStan (phpstan.neon) to enforce coding standards and static analysis. The PHPCS configuration applies the PSR12 standard with additional rules for code structure, naming conventions, and forbidden functions, while excluding specific Doctrine mapping and migration directories from line-length checks. The PHPStan configuration sets the analysis level to 'max' and includes extensions for deprecation rules, Doctrine, PHPUnit, strict rules, and Symfony integration.

config/markup · high confidence

Added PayPal webhook request parser

A new PayPalRequestParser class has been introduced to handle incoming PayPal webhook requests. It validates that requests are POST and JSON, verifies the webhook token against a secret, and delegates payload conversion to the existing PayPalPayloadConverter, ensuring proper parsing and error handling for remote events.

src/Infrastructure/Adapter/PayPal/Webhook · high confidence

Added Symfony console and PHPUnit entry-point scripts

The project now includes executable shell scripts in the bin directory to bootstrap the application and run tests. bin/console initializes the Symfony Kernel and exposes the console application for command-line interactions, while bin/phpunit delegates execution to the PHPUnit library installed in vendor, enabling standard test execution.

bin · high confidence

Added UUID v7 identity generator implementation

The application now includes a concrete implementation of the UUID identity generator interface, located in src/Infrastructure/Uuid. This new UuidIdentityGenerator class utilizes Symfony's Uuid component to generate version 7 UUIDs, providing a standardized method for creating unique identifiers within the infrastructure layer.

src/Infrastructure/Uuid · high confidence

Added ValidationFailedException for HTTP 422 responses

A new ValidationFailedException class has been introduced in the Messenger infrastructure to handle validation errors. This exception extends RuntimeException and is configured to automatically return an HTTP 422 status code. It stores the specific constraint violations, allowing consumers to access the detailed validation failure information via the getViolations method or by using the fromViolations factory method.

src/Infrastructure/Messenger/Exception · high confidence

Added account data fixtures for development and testing

A new Doctrine fixture class (AccountFixture) has been introduced to seed the database with sample account data. This fixture creates an admin account, a standard user account, and ten additional random user accounts, all using a consistent password hash and realistic timestamps. This enables developers and testers to quickly populate the application with valid user data for local development and automated testing environments.

src/Infrastructure/Doctrine/Fixture · high confidence

Added application queries to retrieve account details by ID and for the current signed-in user

New query handlers and DTOs have been added to the application layer to support fetching account information. The \GetAccountById\ query allows retrieving an account's details (ID, email, locale, status, roles, and timestamps) by a specific UUID, while the \GetSigninAccount\ query retrieves the same set of details for the currently authenticated user by resolving their identifier from the authorization token storage. Both queries use Symfony Messenger for handling and return structured JSON-serializable results.

src/Application/Query/GetAccountById · high confidence

Added cache-backed JWT access token revocation

A new \JwtAccessTokenRevokerCache\ implementation has been added to the infrastructure layer to handle JWT access token revocation using a PSR-6 cache pool. This component allows the system to track revoked tokens by storing their identifiers in the cache with a time-to-live (TTL) derived from the token's expiration time, enabling efficient checks via the \isRevoked\ method without requiring a database lookup for every request.

src/Infrastructure/Cache · high confidence

Added domain-specific HTTP exception classes for account operations

Introduced four new exception classes in the account domain to provide structured error handling with automatic HTTP status mapping: AccountAlreadyExistsException (409 Conflict) for duplicate email addresses, AccountInvalidActionException (422 Unprocessable Entity) for invalid account actions, AccountNotFoundException (404 Not Found) for missing accounts, and AccountRevisionConflictException (409 Conflict) for revision conflicts. These exceptions extend RuntimeException and use Symfony's WithHttpStatus attribute to ensure consistent API responses.

src/Domain/Account/Exception · high confidence

Added email notification support for new account registrations

The system now sends a personalized welcome email when a new account is created. This is implemented via a new \AccountRegisteredEventHandler\ that listens for the \AccountRegisteredEvent\, translates the email subject based on the user's locale, and renders the \@emails/account.registered.html.twig\ template. A new \TemplatedEmailNotification\ class bridges Symfony's TemplatedEmail with the Notifier component to ensure the email is correctly formatted and sent to the registered user.

src/Infrastructure/Notifier · high confidence

Added email templates for account registration

New Twig templates have been added to the email presentation layer to support account registration notifications. A new base layout (default/body.html.twig) provides the HTML structure for emails, and a specific template (account.registered.html.twig) extends this layout to display a confirmation message containing the user's email address upon successful account creation.

src/Presentation/Resource/Template/emails · high confidence

Added health status endpoint

A new GET /health endpoint has been introduced to allow users to check the current health status of the application. This controller exposes the health status via a JSON response, integrating with the existing query bus to retrieve the status information.

src/Presentation/Controller/Health · high confidence

Added health status query capability

Introduced a new application-layer query structure for retrieving system health status. This includes a query object, a result DTO that serializes the health check status to JSON, and a message handler that processes the query by invoking the domain Healthcheck service and returning a success response.

src/Application/Query/GetHealthStatus · high confidence

Added infrastructure adapters for HTTP responses and template rendering

Introduced two new infrastructure components: an HTTP client adapter that fetches JSON data from an external service (configured via the HTTPBIN\_URL environment variable) and a Twig-based template renderer. These classes implement application contracts to provide concrete implementations for retrieving external API responses and rendering views, handling errors by wrapping underlying exceptions in domain-specific failure exceptions.

src/Infrastructure/Adapter/Kennethreitz · high confidence

Added infrastructure components for domain event collection and failed message monitoring

This change introduces two new classes in the Messenger infrastructure layer. The \DomainEventCollector\ provides a mechanism to collect, release, and reset domain events within the current request scope, implementing \ResetInterface\ to ensure clean state between requests. The \FailedMessageCounter\ implements the application's \FailedMessageCounterInterface\ by delegating to the Symfony Messenger failed transport, allowing the application to query the number of messages currently in the failure queue.

src/Infrastructure/Messenger · high confidence

Added message middleware for correlation IDs, validation, and domain event handling

The application now includes three new Symfony Messenger middleware components to enhance message processing. The CorrelationIdMiddleware automatically attaches or propagates correlation IDs to messages for better tracing. The MessageValidationMiddleware validates incoming messages using the Symfony Validator before they are processed, throwing a ValidationFailedException if constraints are violated. The DomainEventMiddleware collects domain events generated during message handling and publishes them via the EventMessageBus after the message handler completes, ensuring events are only published if the handler succeeds.

src/Infrastructure/Messenger/Middleware · high confidence

Added password and token-based user authentication models

Introduced new infrastructure classes to support two distinct authentication mechanisms: password-based login and token-based access. The PasswordAuthenticatedUser class now stores user credentials and roles, while the PasswordAuthenticatedUserChecker enforces account activation status by blocking login attempts for disabled accounts. Additionally, the TokenAuthenticatedUser class provides a structure for managing token identifiers, expiration times, and associated user roles.

src/Infrastructure/Security/AuthenticatedUser · high confidence

Added public entry point for the application

A new public/index.php file has been added to serve as the entry point for the application. It initializes the App/kernel using the runtime loader, configuring the kernel based on the APP\_ENV and APP\_DEBUG environment variables.

public · high confidence

Added query support for retrieving accounts by criteria

Users can now retrieve a paginated list of accounts filtered by email and status. This change introduces the GetAccountsByCriteriaQuery, its handler, and the result structure, which maps account details (ID, email, locale, status, roles, and timestamps) into a JSON-serializable format with pagination metadata.

src/Application/Query/GetAccountsByCriteria · high confidence

Added request payload value resolver for strict DTO binding

A new Symfony value resolver has been introduced to automatically deserialize request bodies into strongly-typed Data Transfer Objects (DTOs). This component enforces strict validation by rejecting unknown request parameters and ensuring type correctness, throwing specific exceptions when extra attributes are present or when data fails to normalize to the expected type.

src/Infrastructure/HttpKernel/ValueResolver · high confidence

Admin account management API endpoints

This change introduces a set of new REST API controllers in the Presentation layer for managing user accounts, restricted to users with the ROLE\_ADMIN permission. The endpoints allow administrators to create new accounts (POST /account), retrieve a single account by ID (GET /account/{id}), list accounts filtered by criteria with pagination (GET /account), update account details like email, password, or locale (PATCH /account/{id}), block and unblock accounts (POST /account/{id}/block, POST /account/{id}/unblock), and delete accounts (DELETE /account/{id}). Each controller is wired to its corresponding Application command or query handler and includes OpenAPI documentation for request/response schemas.

src/Presentation/Controller/Account · high confidence

Automatic correlation ID injection for outbound HTTP requests

Outbound HTTP requests now automatically include an X-Correlation-Id header to improve observability and request tracing. This is implemented via a new CorrelationIdHttpClient decorator that wraps the standard Symfony HTTP client, injecting a correlation ID provided by the new CorrelationIdProvider (which generates a UUID v4 if one is not already set). The provider also supports resetting the ID per request context.

src/Infrastructure/HttpClient · high confidence

Enhanced logging with authorization, correlation, and sensitive data protection

The application now includes several Monolog processors to improve log quality and security. The AuthorizationProcessor automatically attaches the current user's identifier and roles to log entries when a security token is present. The CorrelationIdProcessor injects a unique correlation ID into logs to facilitate request tracing. The IntrospectionProcessor adds source file and line number information to help developers locate the origin of log messages. Additionally, the SensitiveDataProcessor, supported by a new SensitiveDataProtector, automatically masks sensitive fields like emails and passwords in log contexts to prevent accidental data exposure.

src/Infrastructure/Monolog · high confidence

Initial Docker configuration for development and production environments

This change introduces the foundational Docker configuration files for the application, establishing the runtime environment for both development and production. It includes PHP settings for development (with Xdebug) and production (with OPcache JIT), an entrypoint script that manages environment-specific setup and commands (application, messenger, migration, quality), Nginx configuration for handling requests and logging, Supervisor configurations for managing Nginx, PHP-FPM, and background messenger workers (domain-events, notifier-emails, webhook-events, scheduler-tasks), and PHP-FPM pool settings.

config/docker · high confidence

Initial Symfony application configuration scaffold

The application now includes the standard Symfony configuration files required to bootstrap the framework. This includes \config/bundles.php\ to register core bundles (such as Doctrine, Security, and Twig) and their environment scopes, \config/services.php\ to enable autowiring and autoconfiguration for the \App\ namespace, \config/preload.php\ to optimize production performance, and \config/reference.php\ which provides IDE autocompletion for service definitions.

config · high confidence

Initial account management command handlers

This change introduces the application-layer command handlers for core account lifecycle operations. Users can now create, update, delete, block, and unblock accounts, as well as sign in and out. The implementation includes command objects with validation (email, password strength, UUIDs), handlers that interact with the account repository and password hasher, and JWT-based authentication flows for signing in and out.

src/Application/Command · high confidence

Initial application kernel setup

The application now includes a base Kernel class (src/Kernel.php) extending Symfony's BaseKernel and utilizing the MicroKernelTrait, establishing the core entry point for the Symfony framework.

src · high confidence

Initial database schema for the account entity

The application now includes the initial database migration to create the 'account' table. This table stores user credentials and profile data, including email, password, locale, roles, and status, along with timestamps for creation, updates, and soft deletion. A unique index on the email column ensures that each active account has a distinct email address.

src/Infrastructure/Doctrine/Migration · high confidence

Initial domain model for account management and localization

This change introduces the core domain entities for the application's account system, including the Account aggregate root with its lifecycle methods (create, register, activate, block, unblock, delete) and status transitions. It also adds supporting value objects and enums such as AccountIdentifier, AccountRole, AccountRoleSet, AccountStatus, and LocaleCode (supporting en-US and uk-UA), along with the AccountRegisteredEvent to track registration actions.

src/Domain/Account · high confidence

Initial implementation of Doctrine-based Account persistence

This change introduces the initial infrastructure for managing user accounts using Doctrine ORM. It adds an \AccountEntityMapper\ to convert between domain \Account\ objects and Doctrine \AccountEntity\ records, and an \AccountEntityRepository\ that implements \AccountRepositoryInterface\. The repository provides capabilities to find accounts by ID or email, search with pagination and filtering, ensure email uniqueness, and save accounts with optimistic locking and soft-delete support.

src/Infrastructure/Doctrine/Repository · high confidence

Initial implementation of Lcobucci JWT access token infrastructure

This change introduces the initial implementation of the JWT access token system using the Lcobucci library. It adds the core infrastructure components in the \src/Infrastructure/Adapter/Lcobucci\ directory, including \JwtConfigurationBag\ for managing signing keys, issuers, and validation constraints (supporting both symmetric HMAC and asymmetric RSA algorithms), \JwtAccessTokenIssuer\ for generating signed tokens with configurable lifetimes and user roles, \JwtAccessTokenParser\ for validating and decoding tokens into \JwtAccessToken\ value objects, and supporting classes like \JwtRegisteredClaims\ and exception handlers. This provides the foundational capability to issue and verify JWT-based access tokens within the application.

src/Infrastructure/Adapter/Lcobucci · high confidence

Introduction of Account Domain Contracts

New interfaces have been added to the Account domain to define core abstractions for account management and security. The AccountPasswordHasherInterface specifies the contract for hashing plain passwords into secure hashes, utilizing PHP's SensitiveParameter attribute for security best practices. The AccountRepositoryInterface defines the data access layer, providing methods to find accounts by ID or email, save account entities, and ensure email uniqueness, along with support for paginated searches by criteria.

src/Domain/Account/Contract · high confidence

Introduction of application-layer contract interfaces

The application layer now exposes a set of new interfaces in the \src/Application/Contract\ directory to define clear boundaries for core capabilities. These include \AuthorizationTokenStorageInterface\ for managing token identifiers and expiration, \JwtAccessTokenIssuerInterface\ and \JwtAccessTokenRevokerInterface\ for JWT lifecycle management, and \CommandMessageBusInterface\ alongside \QueryMessageBusInterface\ to standardize command and query dispatching. Additional contracts such as \FailedMessageCounterInterface\, \HttpbinResponseProviderInterface\, \TwigTemplateRendererInterface\, and \UuidIdentityGeneratorInterface\ provide abstractions for error tracking, external HTTP responses, template rendering, and unique ID generation, respectively.

src/Application/Contract · high confidence

Introduction of base controller with CQRS message bus injection

A new AbstractController class has been added to the presentation layer, extending Symfony's base controller. This class injects CommandMessageBusInterface and QueryMessageBusInterface via its constructor, providing a standardized foundation for controllers to interact with the application's CQRS message buses.

src/Presentation/Controller · high confidence

Introduction of dedicated message bus implementations for commands, queries, and events

The application now includes specific infrastructure classes for handling different types of messages via Symfony Messenger. CommandMessageBus and QueryMessageBus enforce that exactly one handler processes the message, throwing a LogicException if multiple handlers are detected, while EventMessageBus silently ignores events that have no registered handlers. All three buses are configured as lazy services and autowired to their respective Symfony Messenger buses (command.bus, query.bus, event.bus).

src/Infrastructure/Messenger/MessageBus · high confidence

Introduction of domain foundation utilities for immutability and event handling

This change introduces three new components to the domain foundation layer to support robust domain modeling. The ImmutableCloneTrait provides a private withFields method that leverages PHP 8.2's clone with expression to create modified copies of objects, establishing a base for immutability. The DomainEventsTrait builds on this by adding a withEvents method (marked with \#\[NoDiscard\] to prevent ignored side-effects) for appending domain events to an entity, along with a releaseEvents method to retrieve them. Additionally, a new SearchResult class is added as a readonly value object to standardize the structure of paginated search results, containing items, totalCount, pageNumber, and pageSize.

src/Domain/Foundation · high confidence

Introduction of foundational domain value objects

The domain foundation layer now includes four new value objects to enforce type safety and validation for core data types. AbstractUuidIdentifier provides a base for UUID-based identifiers with strict format validation. DateTimeUtc ensures all datetime operations are handled in UTC, offering methods to create instances from the current time, existing interfaces, or convert to standard formats. EmailAddress validates and normalizes email strings, ensuring consistent lowercase storage and equality checks. PasswordHash validates that stored hashes conform to either Bcrypt or Argon2 formats, preventing invalid hash storage.

src/Domain/Foundation/ValueObject · high confidence

Introduction of health check domain models

Added the core domain models for the health check feature: the \HealthStatus\ enum, which defines the 'ok' state and provides a string representation, and the \Healthcheck\ value object, which encapsulates the status and includes a static factory method to create a healthy instance.

src/Domain/Healthcheck · high confidence

Introduction of token storage and password hashing infrastructure

This change introduces new infrastructure components for security handling. The \AuthorizationTokenStorage\ class now implements the \AuthorizationTokenStorageInterface\, providing methods to retrieve the current token identifier, token expiration time, and user identifier by interacting with Symfony's \TokenStorageInterface\ and validating against \TokenAuthenticatedUser\. Additionally, the \AccountPasswordHasher\ class implements \AccountPasswordHasherInterface\, utilizing Symfony's \PasswordHasherFactoryInterface\ to hash plain passwords into \PasswordHash\ value objects for \PasswordAuthenticatedUser\ instances.

src/Infrastructure/Security/TokenStorage · high confidence

JWT access token authentication handler added

A new \JwtAccessTokenHandler\ class has been introduced in the security infrastructure to handle JWT-based access tokens. This component implements Symfony's \AccessTokenHandlerInterface\, parsing incoming tokens via \JwtAccessTokenParser\ and validating them against a revocation list before generating a \UserBadge\ for the authenticated user session.

src/Infrastructure/Security/AccessToken · high confidence

New HTTP exception classes for request validation errors

Added two new exception classes, RequestExtraParamsException and RequestParamTypeException, to the HTTP kernel infrastructure. These exceptions are designed to handle specific request validation failures: the former signals when a request contains unexpected parameters, and the latter indicates when parameters have invalid types. Both are configured to return an HTTP 422 status code and expose detailed constraint violation information to assist in debugging or client-side error handling.

src/Infrastructure/HttpKernel/Exception · high confidence

New HTTP kernel event listeners for correlation IDs, security headers, and exception handling

This change introduces four new Symfony event listeners in the infrastructure layer to enhance request/response handling. The CorrelationIdEventListener injects an X-Correlation-Id header into responses for traceability, while the SecurityHeadersEventListener adds X-Content-Type-Options and X-Frame-Options headers to improve security posture. The KernelExceptionEventListener standardizes error responses by normalizing exceptions, determining HTTP status codes via attributes or interfaces, and logging detailed context. Additionally, the RequestPayloadEventListener normalizes incoming request data and stores it in request attributes for downstream use.

src/Infrastructure/HttpKernel/EventListener · high confidence

New PHP CodeSniffer standards configuration

The project now includes a custom PHP\_CodeSniffer standard under \config/markup/Standards\ to enforce code style and structural rules. This configuration introduces sniffs that restrict allowed PHPDoc annotation tags, enforce strict namespace usage patterns within the \App\ hierarchy, and require explicit type hints for method parameters and return values. It also mandates strict equality operators (\===\/\!==\), requires postfix increment/decrement operators, discourages the use of \else\ statements, and automatically removes unused \use\ imports. Formatting rules enforce trailing commas in multi-line structures, prefer single-quoted strings where possible, and restrict extra whitespace and consecutive empty lines.

config/markup/Standards · high confidence

New authentication API endpoints for account management

The application now exposes a new set of RESTful endpoints under the /auth path to handle user lifecycle and session management. Users can create new accounts via POST /auth/signup (accepting email, password, and locale), authenticate to receive a Bearer token via POST /auth/signin, and invalidate their session via POST /auth/signout. Additionally, authenticated users can retrieve their current account details (ID, email, locale, status, roles, timestamps) via GET /auth/me. These controllers are wired to the application's command and query buses, enforcing full authentication for account retrieval and sign-out operations.

src/Presentation/Controller/Auth · high confidence

New console commands for log management and demo execution

Two new Symfony console commands have been added to the application. The \logs:clear\ command allows users to delete the log file for the current environment, providing feedback on success or failure. The \app:symfony:run\ command serves as a demo tool that iterates through slides from an HTTP response, with an optional \--delay\ argument to control the speed of the progress bar.

src/Presentation/Command · high confidence

New database-backed user provider for Symfony security

A new DatabaseUserProvider has been added to the security infrastructure, implementing Symfony's UserProviderInterface to load user credentials from the database. This component retrieves account details by email address using the AccountRepository and maps them to the PasswordAuthenticatedUser object, enabling authentication against stored user data.

src/Infrastructure/Security/UserProvider · high confidence

New exception classes for Lcobucci JWT validation errors

Added two new exception classes, InvalidConfigurationException and InvalidTokenException, within the Lcobucci adapter infrastructure. InvalidTokenException is annotated to return a 401 HTTP status and provides factory methods for specific token issues such as decoding errors, invalid structure, empty content, expiration, and revocation. InvalidConfigurationException is annotated to return a 500 HTTP status and covers configuration failures like missing token signer setup or empty token subjects.

src/Infrastructure/Adapter/Lcobucci/Exception · high confidence

PayPal payment capture webhook integration

The application now supports receiving and processing PayPal payment capture webhooks. A new payload converter validates incoming webhook data and maps specific PayPal event types (completed, declined, pending, refunded, reversed) to internal domain events. The remote event consumer listens for these mapped events and, upon receiving a 'completed' payment capture, publishes a PaymentReceivedEvent to the internal message bus to trigger subsequent payment processing logic.

src/Infrastructure/Adapter/PayPal/RemoteEvent · high confidence

Scheduled monitoring for failed messenger messages

A new scheduled task has been added to the scheduler that runs every 15 minutes to monitor the messenger failed transport. When unprocessed messages are detected, the system logs an error with the specific count of failed messages, enabling operators to quickly identify and address message processing backlogs.

src/Presentation/Scheduler · high confidence

Structured serialization of HTTP requests and exceptions

The serializer infrastructure now includes dedicated normalizers for converting Symfony Request objects and Throwable exceptions into structured arrays. RequestNormalizer flattens query parameters, route attributes, and file uploads into a unified format while casting string values to appropriate types and stripping internal keys. ExceptionNormalizer converts exceptions into a consistent error response containing a generated code, message, and optional validation violations; in debug mode, it also includes the full stack trace and sensitive violation details (object and invalid value) to aid troubleshooting.

src/Infrastructure/Serializer · high confidence

Behavioural changes

Added HTTP 500 exception adapters for HTTP and template rendering failures

Two new exception classes have been introduced to the infrastructure layer to handle specific failure scenarios with standardized HTTP responses. The \HttpRequestFailedException\ (Kennethreitz adapter) and \RenderingFailedException\ (Sensiolabs adapter) both extend \RuntimeException\ and are annotated with \\#\[WithHttpStatus(statusCode: 500)\]\, ensuring that when these exceptions are thrown, the application automatically returns a 500 Internal Server Error status. Each class provides a static \fromException\ factory method to wrap a previous throwable with a descriptive message ('Httpbin responder encountered an exception.' or 'Template renderer encountered an exception.' respectively), allowing callers to preserve the original error context while signaling a server-side failure to the client.

src/Infrastructure/Adapter/Kennethreitz/Exception, src/Infrastructure/Adapter/Sensiolabs/Exception · high confidence

Custom styling for Swagger UI documentation view

The template for the Swagger UI documentation page has been customized to adjust the visual presentation. The header is now hidden, and specific font sizes and weights are applied to improve readability of API endpoints and parameters. Additionally, margins around the information container and body have been adjusted to provide a tighter layout.

src/Presentation/Resource/Template/bundles/NelmioApiDocBundle · high confidence

Test coverage

Added functional tests for account management and authentication endpoints; Added test bootstrap configuration; Added test fixtures for various account states; Added test support traits for database, HTTP, and messaging; Initial unit test coverage for core domain and infrastructure components.

Dependencies

Initial project setup with Symfony 8.1 and Doctrine 3

The application is initialized as a Symfony 8.1 project, establishing the core framework dependencies (symfony/framework-bundle, symfony/console, etc.) and requiring PHP 8.5. It integrates Doctrine ORM 3.7 and Doctrine DBAL 4.4 for database management, alongside AMQP and Redis extensions for messaging and caching. Development tooling includes PHPUnit 13.3, PHPStan 2.2, and PHPCS 4.0 to ensure code quality and testing standards.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 68 → 66 (-2.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 100 (+0.9)
  • Architecture 72 → 65 (-7.2)
  • Maturity 62 → 60 (-1.8)
  • Readiness 65 → 69 (+4.6)
  • Security 77 → 84 (+7.1)
  • Domain Modelling 100 → 74 (-25.6)

Resolved (22)

  • Change coupling clique: BlockAccountByIdController.php, CreateNewAccountController.php, DeleteAccountByIdController.php, GetAccountByIdController.php, GetAccountsByCriteriaController.php, UnblockAccountByIdController.php, UpdateAccountByIdController.php, GetSigninAccountController.php, SigninIntoAccountController.php, SignupNewAccountController.php, GetHealthStatusController.php (src/Presentation/Controller/Account/BlockAccountByIdController.php)
  • Change coupling: AnnotationTagSniff.php ↔ TrailingCommaMultilineSniff.php (config/markup/Standards/Sniffs/Annotations/AnnotationTagSniff.php)
  • Change coupling: CreateNewAccountCommandHandler.php ↔ SignupNewAccountCommandHandler.php (src/Application/Command/CreateNewAccount/CreateNewAccountCommandHandler.php)
  • ClassStructureSniff.process (cognitive 18) (config/markup/Standards/Sniffs/Classes/ClassStructureSniff.php)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (src/Infrastructure/Doctrine/Repository/Account/AccountEntityRepository.php)
  • Duplicated block (7 lines × 2) (src/Application/Command/CreateNewAccount/CreateNewAccountCommandHandler.php)
  • Duplicated block (9 lines × 2) (src/Infrastructure/Doctrine/Fixture/AccountFixture.php)
  • Duplicated block (9 lines × 2) (src/Infrastructure/Messenger/MessageBus/CommandMessageBus.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Secret: generic-api-key (.env)
  • Secret: generic-api-key (.env)
  • …and 2 more

New (60)

  • Change coupling clique: CreateNewAccountCommand.php, SignupNewAccountCommand.php, UpdateAccountByIdCommand.php (src/Application/Command/CreateNewAccount/CreateNewAccountCommand.php)
  • Change coupling clique: CreateNewAccountController.php, UpdateAccountByIdController.php, SigninIntoAccountController.php (src/Presentation/Controller/Account/CreateNewAccountController.php)
  • Change coupling: Account.php ↔ Healthcheck.php (src/Domain/Account/Account.php)
  • Change coupling: Account.php ↔ Version20200101000000.php (src/Domain/Account/Account.php)
  • Change coupling: DeleteAccountByIdCommandHandler.php ↔ SignupNewAccountCommandHandler.php (src/Application/Command/DeleteAccountById/DeleteAccountByIdCommandHandler.php)
  • Change coupling: DeleteAccountByIdCommandHandler.php ↔ UpdateAccountByIdCommandHandler.php (src/Application/Command/DeleteAccountById/DeleteAccountByIdCommandHandler.php)
  • Change coupling: GetAccountByIdQueryResult.php ↔ GetAccountsByCriteriaQueryResult.php (src/Application/Query/GetAccountById/GetAccountByIdQueryResult.php)
  • Change coupling: GetAccountByIdQueryResult.php ↔ GetSigninAccountQueryResult.php (src/Application/Query/GetAccountById/GetAccountByIdQueryResult.php)
  • Change coupling: GetAccountsByCriteriaController.php ↔ GetSigninAccountController.php (src/Presentation/Controller/Account/GetAccountsByCriteriaController.php)
  • Change coupling: GetSigninAccountController.php ↔ GetHealthStatusController.php (src/Presentation/Controller/Auth/GetSigninAccountController.php)
  • Change coupling: HttpbinResponseProvider.php ↔ TwigTemplateRenderer.php (src/Infrastructure/Adapter/Kennethreitz/HttpbinResponseProvider.php)
  • Change coupling: PasswordAuthenticatedUserChecker.php ↔ DatabaseUserProvider.php (src/Infrastructure/Security/AuthenticatedUser/PasswordAuthenticatedUserChecker.php)
  • Change coupling: SignupNewAccountCommandHandler.php ↔ UpdateAccountByIdCommandHandler.php (src/Application/Command/SignupNewAccount/SignupNewAccountCommandHandler.php)
  • Change-coupling hub: BlockAccountByIdCommandHandler.php → CreateNewAccountCommandHandler.php, DeleteAccountByIdCommandHandler.php, SigninIntoAccountCommandHandler.php, SignupNewAccountCommandHandler.php, UnblockAccountByIdCommandHandler.php, UpdateAccountByIdCommandHandler.php, GetSigninAccountQueryHandler.php (src/Application/Command/BlockAccountById/BlockAccountByIdCommandHandler.php)
  • Change-coupling hub: CreateNewAccountCommandHandler.php → DeleteAccountByIdCommandHandler.php, SignupNewAccountCommandHandler.php, UpdateAccountByIdCommandHandler.php (src/Application/Command/CreateNewAccount/CreateNewAccountCommandHandler.php)
  • Change-coupling hub: GetAccountByIdController.php → GetSigninAccountQueryResult.php, GetAccountsByCriteriaController.php, GetSigninAccountController.php (src/Presentation/Controller/Account/GetAccountByIdController.php)
  • Change-coupling hub: GetAccountByIdQueryHandler.php → BlockAccountByIdCommandHandler.php, CreateNewAccountCommandHandler.php, DeleteAccountByIdCommandHandler.php, SigninIntoAccountCommandHandler.php, SignupNewAccountCommandHandler.php, UnblockAccountByIdCommandHandler.php, UpdateAccountByIdCommandHandler.php, GetAccountsByCriteriaQueryHandler.php, GetSigninAccountQueryHandler.php (src/Application/Query/GetAccountById/GetAccountByIdQueryHandler.php)
  • Change-coupling hub: GetSigninAccountQueryHandler.php → CreateNewAccountCommandHandler.php, DeleteAccountByIdCommandHandler.php, SigninIntoAccountCommandHandler.php, SignupNewAccountCommandHandler.php, UpdateAccountByIdCommandHandler.php (src/Application/Query/GetSigninAccount/GetSigninAccountQueryHandler.php)
  • Change-coupling hub: RenderingFailedException.php → TwigTemplateRendererInterface.php, HttpbinResponseProvider.php, InvalidTokenException.php (src/Infrastructure/Adapter/Sensiolabs/Exception/RenderingFailedException.php)
  • Change-coupling hub: UnblockAccountByIdCommandHandler.php → CreateNewAccountCommandHandler.php, DeleteAccountByIdCommandHandler.php, SigninIntoAccountCommandHandler.php, SignupNewAccountCommandHandler.php, UpdateAccountByIdCommandHandler.php, GetSigninAccountQueryHandler.php (src/Application/Command/UnblockAccountById/UnblockAccountByIdCommandHandler.php)
  • …and 40 more

Changes since last survey

  • 44 commits — 44 feature/other, 0 fixes

By area

  • (root) — 30 commits
  • src/Infrastructure — 8 commits
  • src/Presentation — 2 commits
  • config/packages — 1 commit
  • config/reference.php — 1 commit
  • src/Application — 1 commit
  • tests/Functional — 1 commit

Notable commits

  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • change: Initial commit
  • …and 24 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

opifex/symfony was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 8e662778031cd416b7f0dc58c8a572973c8e328a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.